We found results for “”
CVE-2025-24021
Good to know:
Date: May 14, 2025
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.
Severity Score
Severity Score
Weakness Type (CWE)
Missing Authorization
CWE-862Top Fix
Upgrade Version
Upgrade to version https://github.com/Combodo/iTop.git - 3.2.1;https://github.com/Combodo/iTop.git - 3.1.3;https://github.com/Combodo/iTop.git - 2.7.12
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


